Junglewise Threat Intelligence

CVE-2026-14151: Google Chrome inappropriate implementation in AI

CVE-2026-14151 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the AI component of Google Chrome, a widely used web browser. If an attacker has already partially compromised the browser's rendering process, they could use a specially crafted web page to break out of the browser's security sandbox. This could allow the attacker to gain broader access to the underlying operating system, potentially leading to unauthorized data access or further system compromise.

Technical details

This vulnerability is classified as an inappropriate implementation within the AI component of Google Chrome. The flaw allows a remote attacker to achieve a sandbox escape, provided they have already achieved code execution within the renderer process (a "chained" attack). The exploit is triggered via a specially crafted HTML page. The vulnerability was addressed in Google Chrome version 150.0.7871.47. Chromium security researchers have rated this as Low severity, likely due to the precondition of a prior renderer compromise.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats